Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.1VMware

High [CVE-2026-41717] Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability.

Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs during parameter binding when a user-defined repository query method is annotated with @Query and utilizes a capture-all placeholder. Affected versions: Spring Data MongoDB 5.0.0 through 5.0.5; 4.5.0 through 4.5.11; 4.4.0 through 4.4.14; 4.3.0 through 4.3.16; 4.2.0 through 4.2.15; 4.1.0 through 4.1.14; 4.0.0 through 4.0.15; 3.4.0 through 3.4.19.

CVE-2026-41717
Unclassified
Jun 10, 2026
High7.5VMware

High [CVE-2026-41716] Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing…

Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion through repeated requests. Affected versions: Spring Data Commons 2.7.0 through 2.7.19; 3.3.0 through 3.3.16; 3.4.0 through 3.4.14; 3.5.0 through 3.5.11; 4.0.0 through 4.0.5.

CVE-2026-41716
Unclassified
Jun 10, 2026
High7.5VMware

High [CVE-2026-41695] Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion

Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings are passed to MappingContext property path resolution. Affected versions: Spring Data Commons 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14.

CVE-2026-41695
Unclassified
Jun 10, 2026
High7.6VMware

High [CVE-2026-41003] Spring Security: attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms gene…

An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.

CVE-2026-41003
Tanzu / Spring
Jun 10, 2026
High7.3VMware

High [CVE-2026-40993] Spring Security: attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asser…

An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the columns containing the collection of verification or encryption credentials (verification_credentials and encryption_credentials, respectively). Affected versions: Spring Security 7.0.0 through 7.0.5.

CVE-2026-40993
Tanzu / Spring
Jun 10, 2026
High7.5VMware

High [CVE-2026-40988] Spring Security: application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may…

An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded writer that inflates the compressed SAML payload into memory. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.

CVE-2026-40988
Tanzu / Spring
Jun 10, 2026
High8.1VMware

High [CVE-2026-41855] Spring Framework: In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.sp…

In an untrusted JMS environment, org.springframework.jms.support.converter. MappingJackson2MessageConverter and org.springframework.jms.support.converter. JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized actions via gadget class deserialization. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVE-2026-41855
Tanzu / Spring
Jun 9, 2026
High7.5VMware

High [CVE-2026-41850] Spring Framework: Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial…

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability. Affected product named by the advisory: Spring Framework.

CVE-2026-41850
Tanzu / Spring
Jun 9, 2026
High7.5VMware

High [CVE-2026-41849] Spring Framework: integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL).

An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected product named by the advisory: Spring Framework.

CVE-2026-41849
Tanzu / Spring
Jun 9, 2026
High7.1VMware

High [CVE-2026-41845] Spring Framework: Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may

Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected product named by the advisory: Spring Framework.

CVE-2026-41845
Tanzu / Spring
Jun 9, 2026
High7.5VMware

High [CVE-2026-41842] Spring Framework: Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.

Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected product named by the advisory: Spring Framework.

CVE-2026-41842
Tanzu / Spring
Jun 9, 2026
High7.4VMware

High [CVE-2026-41720] Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username is paired…

Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username is paired with an empty or null password.

CVE-2026-41720
Unclassified
Jun 9, 2026
High7.5VMware

High [CVE-2026-41007] Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings.

Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings.

CVE-2026-41007
Unclassified
Jun 9, 2026
High7.5VMware

High [CVE-2026-41006] Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type…

Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations.

CVE-2026-41006
Unclassified
Jun 9, 2026
High7.5VMware

High [CVE-2026-40984] Micrometer HTTP server instrumentations DoS vulnerability

In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.

CVE-2026-40984
Unclassified
Jun 9, 2026
High7.5VMware

High [CVE-2026-40983] In Micrometer, it is possible for a user to provide specially crafted gRPC requests

In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition.

CVE-2026-40983
Unclassified
Jun 9, 2026
High8.0VMware

High [CVE-2026-41724] VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with…

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.

CVE-2026-41724
Cloud Foundation
Jun 8, 2026
High8.2VMware

High [CVE-2026-41010] BOSH: ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs'…

ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where name returns @job_meta['name'], a value taken verbatim from the jobs: array of the attacker-supplied release.MF inside the uploaded tarball. These paths are then interpolated into a shell string: Bosh::Common::Exec.sh("tar -C #{job_dir} -xf #{job_tgz} 2>&1",:on_error =>:return). Bosh::Common::Exec.sh executes via %x{#{command}} (bosh-common/lib/bosh/common/exec.rb:53), i.e. /bin/sh -c, so any shell metacharacters in name are interpreted. FileUtils.mkdir_p(job_dir) on line 49 creates the literal directory (no shell) and succeeds even when the name contains $()/;, so execution reaches the sh call.

CVE-2026-41010
Tanzu / Spring
Jun 4, 2026
High8.8VMware

High [CVE-2026-41860] BOSH: CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM.

CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an attacker to intercept traffic between bosh-monitor and the BOSH director or UAA and steal credentials.

CVE-2026-41860
Tanzu / Spring
Jun 4, 2026
High7.8VMware

High [CVE-2026-41859] network man-in-the-middle between nats-sync and the BOSH director

A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and can tamper with the VM list that is written into the NATS authorization file. Stolen credentials grant administrative director access. UsersSync#bosh_api_response_body builds a Net::HTTP client with verify_mode = OpenSSL::SSL::VERIFY_NONE for every director call (/info, /deployments, /deployments//vms).

CVE-2026-41859
Tanzu / Spring
Jun 4, 2026